US5489896AExpiredUtility

Network with a security capability

Assignee: LANNET DATA COMMUNICATIONS LTDPriority: Oct 18, 1992Filed: Feb 12, 1993Granted: Feb 6, 1996
Est. expiryOct 18, 2012(expired)· nominal 20-yr term from priority
H04L 12/4135H04L 43/00H04L 43/18H04L 12/40013H04L 12/22H04L 12/40032H04L 63/0227H04L 12/413
39
PatentIndex Score
22
Cited by
12
References
22
Claims

Abstract

A network having a security capability where the network includes a data bus, a plurality of stations connected to the data bus and a security unit which monitors traffic on the data bus and only enables authorized data to flow along the data bus.

Claims

exact text as granted — not AI-modified
We claim: 
     
       1. A network having a security capability, the network comprising: a data bus;   a plurality of stations connected to the data bus; and   a security unit which monitors traffic on said data bus and only enables authorized data to flow along said data bus by causing a collision on said data bus when unauthorized traffic is detected.   
     
     
       2. A network according to claim 1 and wherein said data bus and said security unit are part of a hub. 
     
     
       3. A network according to claim 1 and characterized in that said network is a local area network (LAN). 
     
     
       4. A network according to claim 3 and characterized in that said network is a carrier sensing multiple access/collision detection type of LAN. 
     
     
       5. A network according to claim 1 and wherein said security unit comprises a packet blocker operating in accordance with a protocol of said network and operative when unauthorized communication is requested. 
     
     
       6. A network according to claim 1 wherein said traffic comprises a multiplicity of data packets each having source and destination addresses and wherein said security unit comprises a plurality of correlators for determining that said source and destination addresses indicate an authorized communication. 
     
     
       7. A network according to claim 6 wherein each station is connected to said data bus via a port having a port address and wherein one of said correlators correlates said source address with an authorized port address. 
     
     
       8. A method of securing a network having at least one hub, the method comprising: sending blocks of data on a data bus of said hub, wherein said blocks of data each comprise at least source and destination addresses for every block of data sent on said data bus of said hub, determining if said addresses conform to a stored set of access rules; and   causing a collision on the network if the output of said step of determining is false.   
     
     
       9. A method according to claim 8 and wherein said set of access rules includes the rule that said source station address must be among a list of authorized source station addresses. 
     
     
       10. A method according to claim 8 and wherein said set of access rules includes the rule that said source station must be physically connected to an authorized port address. 
     
     
       11. A method according to claim 9 and wherein said set of access rules includes the rule that said source station must be physically connected to an authorized port address. 
     
     
       12. A method according to claim 8 and wherein said set of access rules includes the rule that said destination station address must be in a list of authorized destination station addresses for said source station address. 
     
     
       13. A method according to claim 9 and wherein said set of access rules includes the rule that said destination station address must be in a list of authorized destination station addresses for said source station address. 
     
     
       14. A method according to claim 10 and wherein said set of access rules includes the rule that said destination station address must be in a list of authorized destination station addresses for said source station address. 
     
     
       15. A method according to claim 11 and wherein said set of access rules includes the rule that said destination station address must be in a list of authorized destination station addresses for said source station address. 
     
     
       16. A security unit for a network having a data bus to which a plurality of stations are connected, comprising a traffic monitor which monitors traffic on said data bus and a collision mechanism which only enables authorized data to flow along said data bus by causing a collision on said data bus when unauthorized traffic is detected. 
     
     
       17. A security unit according to claim 16 and wherein said data bus and said security unit are part of a hub. 
     
     
       18. A security unit according to claim 16 and comprising a packet blocker operating in accordance with a protocol of said network and operative when unauthorized communication is requested. 
     
     
       19. A security unit according to claim 16 wherein said traffic comprises a multiplicity of data packets each having source and destination addresses and wherein said security unit comprises a plurality of correlators for determining that said source and destination addresses indicate an authorized communication. 
     
     
       20. A security unit according to claim 19 wherein each station is connected to said data bus via a port having a port address and wherein one of said correlators correlates said source address with an authorized port address. 
     
     
       21. A method of securing a network comprising: sending blocks of data on a data bus of said network, wherein said blocks of data comprise at least a source address and a port address to which said source is connected;   determining if said source address and said port address conform to a stored set of allowable source address and port address combinations; and   denying access to the network for data blocks whose source address and port address do not conform to said stored set of allowable combinations by causing a collision on said data bus.   
     
     
       22. A method of securing a network comprising: sending blocks of data on a data bus of said network; causing a collision on the network if the blocks do not conform to a stored set of access rules.

Join the waitlist — get patent alerts

Track US5489896A — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.